What Did the AI Do, and Who Approved It?
This series has now put AI to work across the control layer: preparing financials, supporting safety, retrieving specifications, tracking contract clocks. Every one of those systems acts — it retrieves, drafts, flags, chases, and sends. Which forces the closing question of the control layer, the one an insurer, an auditor, an inspector, or opposing counsel will eventually ask in some form:
What did the system do, who told it to, who approved the result, and how do you know?
Companies that can answer from a log have governance. Companies that answer from memory have exposure with good intentions.
The four registers
Governance for a contractor-scale AI deployment is not an enterprise compliance program. It is four lists, written down before go-live:
1. Access — who sees what. Information in a contracting company has natural boundaries: crews need procedures and their job's documents; PMs need their jobs' costs and contracts; bookkeeping needs financials; the owner sees across. An AI layer dissolves those boundaries by default — a system that has ingested everything will answer anyone about anything. Scoping is therefore a design decision, not a feature: the foreman's assistant answers safety and job questions; it does not know what the company's margin is, and neither does whoever borrows his phone.
2. Approval — who owns which consequences. The series boundary says humans decide; this register names them. Invoices: who approves. Payments: who. Outbound notices under a contract: who. Safety answers that leave the controlled library: escalation to whom. The register is boring by design — its whole function is that no consequential action has an ambiguous owner, which is precisely the property most companies discover they lack during the post-incident reconstruction.
3. Activity — what happened. Every retrieval, draft, flag, and send, timestamped, with the source behind it. This is cheap to keep and impossible to reconstruct. It also quietly improves the systems themselves: the log of what crews ask and where the assistant escalated is a map of what your documentation fails to answer.
4. Change — who altered the machinery. Prompts, source libraries, permissions, and approval rules will all be edited over time. Unlogged edits to the safety library or the billing rules are how a well-governed system decays into an ungoverned one with a governance binder.
Why this deserves its own post
Because the industry's failure pattern is already visible in miniature. Construction disputes have always turned on documentation — and the companies that lose them are rarely the ones that did the work wrong, but the ones that cannot produce the record. AI multiplies the volume of company actions per day; it either multiplies the record with it, or multiplies the gap.
There is also a nearer-term, unglamorous payoff: insurability and auditability are becoming procurement questions. GCs vet subs' safety documentation today; owner and insurer questionnaires about data handling and decision controls are the same instinct moving upstream. A four-register answer — here is who can access, who approves, what ran, and what changed — is the kind of answer that wins prequalification paperwork, not just lawsuits.
The control layer, complete
With governance in place, the control layer this series set out to build is whole: financial intelligence watching the money, safety systems that retrieve and escalate, jurisdictional intelligence with provenance, contract clocks that never sleep, and an audit spine under all of it. None of it decides. All of it prepares, records, and reports to accountable humans — faster than any staffing plan could.
What remains of the four-system frame is the system that makes the other three compound: the one that learns. Next week: turning every closed job into the company's memory — before the people who are that memory retire.